Apple has finally patched a flaw in its paid Hide My Email tool that was quietly unmasking subscribers’ actual inbox addresses for over a year.
Apple confirmed it deployed a software patch on July 3 to fix a vulnerability in Hide My Email, an iCloud+ feature that creates anonymous email aliases for signing up to websites and services without exposing a user’s primary address.
The issue first came to light publicly in early July after 404 Media reported that Apple had known about the flaw for more than a year.
According to the publication, security researcher Tyler Murphy, co-founder of EasyOptOuts, first reported the bug to Apple in June 2025 and spent months exchanging reports with the company as it investigated and attempted to resolve the issue. Apple told 404 Media the July 3 patch “has fully resolved the issue.”
The disclosure comes as Apple faces a proposed class-action lawsuit alleging the company continued marketing Hide My Email as a privacy feature despite knowing about the flaw.
How the vulnerability worked
Hide My Email generates random email addresses that forward messages to a user’s real inbox, helping reduce spam and limit the exposure of personal email addresses. Before the fix, however, a carefully targeted email that was rejected as spam could expose the recipient’s actual email address in mail server logs, defeating the feature’s core privacy purpose.
Murphy and EasyOptOuts co-founder Ben Weiner cautioned that some privacy risks may persist because email providers often retain historical mail logs.
Conflicting reports over the rollout
Although Apple says the issue was fully resolved on July 3, AppleInsider reported that it was still able to reproduce the behavior on July 17 before later confirming it could no longer do so. The publication said Apple has not explained whether the patch rolled out in stages or why the vulnerability remained reproducible during its testing.
Both Murphy and Weiner have since acknowledged that the underlying bug has been fixed, while maintaining that historical data retained in third-party mail logs could continue to pose a privacy concern for older aliases.
Privacy promises face new scrutiny
The incident highlights the challenges technology companies face when selling privacy-focused services as paid products. Hide My Email is part of Apple’s iCloud+ subscription, and its value depends on keeping users’ real email addresses hidden.
While there is no public evidence that the flaw was exploited on a large scale or that it exposed passwords or account access, the bug undercut one of the feature’s central privacy guarantees.
For consumers, the fix restores protection going forward. However, users who created Hide My Email aliases before early July 2026 may still need to assume those addresses could exist in archived mail logs outside Apple’s control.
Also read: Microsoft’s July 2026 Patch Tuesday fixed a record 570 security flaws, including three zero-days and two exploited bugs.
Read the full article here